Remote VASP serving residents in Montenegro
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Montenegro with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD): Implementing robust KYC procedures for all clients under the Law on Prevention of Money Laundering and Terrorism Financing.
- Ongoing Monitoring: Monitoring transactions and client relationships for suspicious activities.
- Reporting: Filing Suspicious Transaction Reports (STRs) to the Financial Intelligence Unit (FZPCG/USPNFT).
- Risk Assessment: Conducting a comprehensive ML/TF risk assessment.
- Internal Controls: Establishing internal policies, procedures and controls for AML/CFT.
- AML Officer: Appointing a designated AML Officer and providing regular staff training.
- Travel Rule obligations: Collect required originator and beneficiary information for VA transfers, transmit securely, screen for sanctions/suspicious activity, and respond to authority requests.
- All VASPs are 'obliged entities' under the AML law regardless of fiat handling.
Key Restrictions
- Must be incorporated in Montenegro as a legal entity (e.g., LLC) with the Central Registry of Commercial Entities (CRPS).
- Must have a registered office and local management/personnel, including a local AML Officer.
- Must obtain a VASP license from the Capital Market Authority (KAP) under the Law on Blockchain, Digital Assets and Individual Digital Identifiers (Official Gazette No. 80/23).
- Licensing conditions include minimum capital requirements, guarantees for liabilities, adequate organizational structure, technical/security measures, cybersecurity certificate, client asset protection measures, and fit-and-proper requirements for management.
- If handling fiat currency, may also require a payment services or e-money license from the Central Bank of Montenegro (CBCG) with minimum capital requirements (€20,000–€125,000+).
- If VA held in custody are deemed securities, a license from KHOV (Capital Market Commission) may also be required.
Key Risks
- Unlicensed cross-border remote operation without a local entity exposes operators to enforcement action by the Financial Intelligence Unit (USPNFT), KAP, and criminal prosecution.
- Penalties include significant administrative fines, revocation of licenses, and criminal charges for severe non-compliance.
- Montenegro has demonstrated willingness to prosecute high-profile crypto figures (e.g., Do Kwon case — prison sentence for document forgery, ongoing extradition).
- Regulatory framework is still developing; subordinate legislation and guidance from KAP and CBCG are still expected, creating some implementation ambiguity.
- Eventual need to harmonize with EU MiCA regulation as Montenegro is an EU candidate country, creating future regulatory uncertainty.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
An entity generally needs to be incorporated in Montenegro to conduct business activities and be subject to local regulation.
A registered office and local management/personnel, including a local AML Officer, would typically be expected for AML compliance.
Company Registration: Establish a legal entity (e.g., LLC) in Montenegro with the Central Registry of Commercial Entities (CRPS).
AML Framework Implementation: Develop and implement comprehensive AML/CTF policies, procedures, and controls, appoint an AML Officer, and conduct a risk assessment.
AML/KYC (Anti-Money Laundering / Know Your Customer): This is the most critical requirement for any VASP operating in Montenegro.
Customer Due Diligence (CDD): Implementing robust KYC procedures for all clients.
Ongoing Monitoring: Monitoring transactions and client relationships for suspicious activities.
Reporting: Reporting suspicious transactions (STRs) to the Financial Intelligence Unit (FZPCG).
Risk Assessment: Conducting a comprehensive risk assessment of ML/TF risks.
Internal Controls: Establishing internal policies, procedures, and controls for AML/CTF.
AML Officer: Appointment of a designated AML Officer and providing regular training to staff.
All exchanges, regardless of fiat handling, are considered "obligated entities" under AML laws and must comply with those provisions.
There are no specific capital requirements for being a VASP solely under AML obligations.
However, if a license from the CBCG (for payment services/e-money) or KHOV (for investment services) is required, then specific capital requirements would apply based on those respective laws. For instance, payment institutions have minimum capital requirements (e.g., €20,000 to €125,000 depending on services).
Law on Prevention of Money Laundering and Terrorism Financing (Zakon o sprječavanju pranja novca i finansiranja terorizma): This is the primary legislation. While an official English translation with a direct URL might be hard to find, the official Montenegrin legal gazette (Službeni list Crne Gore) publishes it. The most relevant amendments were made in 2021 to address virtual assets.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Transfer of virtual assets.
Collect required originator and beneficiary information.
Transmit this information securely and reliably to the beneficiary VASP (or store it for non-VASP beneficiaries).
Screen transactions for sanctions compliance and suspicious activity.
Respond to requests for information from competent authorities.
Administrative Fines: Significant monetary penalties for legal entities and responsible persons within those entities.
Criminal Charges: In cases of severe or intentional non-compliance, particularly where money laundering or terrorism financing is involved, criminal charges can be brought against individuals and corporate officers.
Legal entity established in Montenegro.
Licensing Conditions (Article 21): Applicants for a VASP license must meet several conditions, including:
Minimum capital requirements and guarantees for covering potential liabilities.
Measures for the protection of client assets.
Possession of a cybersecurity certificate.
Compliance with AML/CFT regulations.
Definition of VASP: Article 2(1)(7) defines a "virtual asset service provider" as a legal entity that, as its regular business activity, provides one or more of the virtual asset services specified in Article 18.
Licensing Authority: The Capital Market Authority (KAP) is responsible for issuing, supervising, and revoking licenses for VASPs (Article 20).
Law on Blockchain, Digital Assets and Individual Digital Identifiers (Zakon o blokčejnu, digitalnoj imovini i individualnim digitalnim identitetima) - Official publication in the "Official Gazette of Montenegro," No. 80/23.
Article 21(1)(9) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers explicitly requires VASPs to implement "measures for the protection of client assets." This typically implies segregation, ensuring that client assets are identifiable and separate from the VASP's own assets, to prevent commingling and protect clients in case of VASP insolvency. While the law doesn't detail how assets must be segregated (e.g., separate wallets, omnibus accounts with clear ledgering), the requirement for "measures for the protection of client assets" is the legal basis.
Article 21(1)(7) of the Law on Blockchain, Digital Assets and Individual Digital Identifiers states that a VASP must meet "minimum capital requirements" and provide "guarantees for the coverage of potential liabilities arising from the provision of virtual asset services."
Do Kwon and his associate were convicted in Montenegro for using forged passports and served their sentences.
MONEYVAL Follow-Up Report (May 2023): This report by Moneyval (Council of Europe anti-money laundering body) provides a detailed assessment of Montenegro's compliance with FATF Recommendations. It explicitly states Montenegro's compliance with Recommendation 15 (Virtual Assets and VASPs) and the implementation of the Travel Rule.
Financial Intelligence Unit (FIU) of Montenegro (Uprava za sprečavanje pranja novca i finansiranja terorizma - USPNFT): This is the main supervisory body for AML/CFT compliance, including for VASPs. Their website may contain guidance.
Payment Processors (Crypto-native/Crypto-to-Crypto):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP cannot serve Montenegro residents from abroad without a local entity; it must incorporate in Montenegro, obtain a VASP license from the Capital Market Authority (KAP) under the Blockchain Law, comply with full AML/CFT obligations supervised by the FIU, and if handling fiat may need a separate CBCG payment services license.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?